Real-world descriptions of how a group, tool or campaign used a technique.
76 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
GroupOilRig | OilRig has used credential dumping tools such as Mimikatz to steal credentials to accounts logged into the compromised system and to Outlook Web Access. |
| T1003.004 LSA Secrets |
GroupOilRig | OilRig has used credential dumping tools such as LaZagne to steal credentials to accounts logged into the compromised system and to Outlook Web Access. |
| T1003.005 Cached Domain Credentials |
GroupOilRig | OilRig has used credential dumping tools such as LaZagne to steal credentials to accounts logged into the compromised system and to Outlook Web Access. |
| T1005 Data from Local System |
GroupOilRig | OilRig has used PowerShell to upload files from compromised systems. |
| T1007 System Service Discovery |
GroupOilRig | OilRig has used |
| T1008 Fallback Channels |
GroupOilRig | OilRig malware ISMAgent falls back to its DNS tunneling mechanism if it is unable to reach the C2 server over HTTP. |
| T1012 Query Registry |
GroupOilRig | OilRig has used |
| T1016 System Network Configuration Discovery |
GroupOilRig | OilRig has run |
| T1021.001 Remote Desktop Protocol |
GroupOilRig | OilRig has used Remote Desktop Protocol for lateral movement. The group has also used tunneling tools to tunnel RDP into the environment. |
| T1021.004 SSH |
GroupOilRig | OilRig has used Putty to access compromised systems. |
| T1025 Data from Removable Media |
GroupOilRig | OilRig has used Wireshark’s usbcapcmd utility to capture USB traffic. |
| T1027.005 Indicator Removal from Tools |
GroupOilRig | OilRig has tested malware samples to determine AV detection and subsequently modified the samples to ensure AV evasion. |
| T1027.013 Encrypted/Encoded File |
GroupOilRig | OilRig has encrypted and encoded data in its malware, including by using base64. |
| T1033 System Owner/User Discovery |
GroupOilRig | OilRig has run |
| T1036 Masquerading |
GroupOilRig | OilRig has used .doc file extensions to mask malicious executables. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupOilRig | OilRig has named a downloaded copy of the Plink tunneling utility as \ProgramData\Adobe.exe. |
| T1046 Network Service Discovery |
GroupOilRig | OilRig has used the publicly available tool SoftPerfect Network Scanner as well as a custom tool called GOLDIRONY to conduct network scanning. |
| T1047 Windows Management Instrumentation |
GroupOilRig | OilRig has used WMI for execution. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
GroupOilRig | OilRig has exfiltrated data via Microsoft Exchange and over FTP separately from its primary C2 channel over DNS. |
| T1049 System Network Connections Discovery |
GroupOilRig | OilRig has used |
| T1053.005 Scheduled Task |
GroupOilRig | OilRig has created scheduled tasks that run a VBScript to execute a payload on victim machines. |
| T1056.001 Keylogging |
GroupOilRig | OilRig has employed keyloggers including KEYPUNCH and LONGWATCH. |
| T1057 Process Discovery |
GroupOilRig | OilRig has run |
| T1059 Command and Scripting Interpreter |
GroupOilRig | OilRig has used various types of scripting for execution. |
| T1059.001 PowerShell |
GroupOilRig | OilRig has used PowerShell scripts for execution, including use of a macro to run a PowerShell command to decode file contents. |
| T1059.003 Windows Command Shell |
GroupOilRig | OilRig has used macros to deliver malware such as QUADAGENT and OopsIE. OilRig has used batch scripts. |
| T1059.005 Visual Basic |
GroupOilRig | OilRig has used VBScript macros for execution on compromised hosts. |
| T1068 Exploitation for Privilege Escalation |
GroupOilRig | OilRig has exploited the Windows Kernel Elevation of Privilege vulnerability, CVE-2024-30088. |
| T1069.001 Local Groups |
GroupOilRig | OilRig has used |
| T1069.002 Domain Groups |
GroupOilRig | OilRig has used |
| T1070.004 File Deletion |
GroupOilRig | OilRig has deleted files associated with their payload after execution. |
| T1071.001 Web Protocols |
GroupOilRig | OilRig has used HTTP for C2. |
| T1071.004 DNS |
GroupOilRig | OilRig has used DNS for C2 including the publicly available |
| T1078 Valid Accounts |
GroupOilRig | OilRig has used compromised credentials to access other systems on a victim network. |
| T1078.002 Domain Accounts |
GroupOilRig | OilRig has used an exfiltration tool named STEALHOOK to retreive valid domain credentials. |
| T1082 System Information Discovery |
GroupOilRig | OilRig has run |
| T1087.001 Local Account |
GroupOilRig | OilRig has run |
| T1087.002 Domain Account |
GroupOilRig | OilRig has run |
| T1105 Ingress Tool Transfer |
GroupOilRig | OilRig had downloaded remote files onto victim infrastructure. |
| T1110 Brute Force |
GroupOilRig | OilRig has used brute force techniques to obtain credentials. |
| T1112 Modify Registry |
GroupOilRig | OilRig has used reg.exe to modify system configuration. |
| T1113 Screen Capture |
GroupOilRig | OilRig has a tool called CANDYKING to capture a screenshot of user's desktop. |
| T1115 Clipboard Data |
GroupOilRig | OilRig has used infostealer tools to copy clipboard data. |
| T1119 Automated Collection |
GroupOilRig | OilRig has used automated collection. |
| T1120 Peripheral Device Discovery |
GroupOilRig | OilRig has used tools to identify if a mouse is connected to a targeted system. |
| T1133 External Remote Services |
GroupOilRig | OilRig uses remote services such as VPN, Citrix, or OWA to persist in an environment. |
| T1137.004 Outlook Home Page |
GroupOilRig | OilRig has abused the Outlook Home Page feature for persistence. OilRig has also used CVE-2017-11774 to roll back the initial patch designed to protect against Home Page abuse. |
| T1140 Deobfuscate/Decode Files or Information |
GroupOilRig | A OilRig macro has run a PowerShell command to decode file contents. OilRig has also used certutil to decode base64-encoded files on victims. |
| T1195 Supply Chain Compromise |
GroupOilRig | OilRig has leveraged compromised organizations to conduct supply chain attacks on government entities. |
| T1201 Password Policy Discovery |
GroupOilRig | OilRig has used net.exe in a script with |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.